Privacy Policy

Effective date: 2026-05-04  ·  App version: 2.0.0+

This policy describes how the Oops I'm Late! mobile application (the "App") collects, uses, and shares information.

The App is published by Alex Reich ("we", "us"). Contact: privacy@oopsimlate.com.


1. Summary in plain English

2. Categories of data we touch, and where each goes

CategorySourceStored whereSent off-device?
Calendar events (title, start, location text, attendee emails)iOS calendarDevice only (RAM + local storage)No
GPS coordinates (lat, lon, accuracy, heading, speed)Device GPSDevice only — used for live ETA computationOnly with traffic-aware ETA enabled (Pro tier): coarse rounded coordinates + appointment endpoint, sent to our routing proxy
Contacts (name, phone, email)Device contacts (you pick which to import)Device onlyNo
Microphone (during hands-free confirmation)Device microphoneNot retained — streamed to platform STT only while the confirmation prompt is activeDepends on platform speech recognition (Apple on iOS, Google on Android); see their policies
SMS / email message textYou compose / we templateDevice only — handed to system SMS or email composerNo (we don't send messages directly)
Diagnostic telemetry (anonymized)App generatesDevice by default; included in crash report only if you enable Crash ReportingOnly if Crash Reporting toggle is ON
ML trip telemetry (predicted vs actual ETA pairs)App generates during tripsDevice only by defaultOnly if you opt in under Settings → ML Telemetry
Subscription / entitlement stateApp Store / Google Play purchase receiptsDevice + RevenueCatYes — to validate purchase status

3. Permissions and how to revoke

Android: revoke any permission in Settings → Apps → Oops I'm Late! → Permissions. Background location is requested separately and only to detect that you are running late while the App is closed; you can choose "Allow only while using the app" instead.

We do not request permissions speculatively. If a permission is denied the App degrades gracefully rather than re-prompting.

4. Off-device transmissions in detail

Traffic ETA proxy (api.oopsimlate.com): when you enable Traffic Boost (Pro tier) the App sends each ETA refresh as: rounded current coordinate, destination coordinate, travel mode. We do not transmit appointment titles, attendee identities, or message content. Requests are authenticated with an anonymous installation identifier — no account or email is required.

Crash reports (Sentry, optional): tagged with anonymized install ID, app version, OS version, and stack traces. Personally identifying fields are scrubbed before send. Disable any time in Settings → Privacy → Crash reporting.

ML trip telemetry (optional, Basic+): aggregated GPS-derived features (speed, accuracy, distance remaining, time-of-day) and predicted vs actual ETA. No raw trace, no destination, no contact. Disable any time.

App store receipts: relayed via RevenueCat purely to validate Basic / Pro subscription status. No usage data.

5. Data retention

DataRetention
Calendar eventsHeld in RAM only; never persisted
GPS history (Free)Up to 5-minute rolling buffer in RAM; never persisted
GPS history (Basic / Pro, on-device)Encrypted at-rest on device; cleared after appointment ends or on user delete
Contacts you've importedUntil you remove them in Settings
Crash reports90 days at Sentry, then deleted
ML trip telemetry365 days at our backend, then aggregated and the raw rows deleted
Subscription receiptsFor the life of the subscription per RevenueCat policy

6. Your rights

7. Children

The App is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect data from children. If you believe a child has provided data, email privacy@oopsimlate.com and we will delete it.

8. Changes to this policy

We will update the "Effective date" at the top when this policy changes in any material way. We will surface material changes in-app on next launch.

9. Apple App Privacy nutrition labels

Apple categoryLinked to user?Used for tracking?
Contact Info — Email Address (attendees only, on-device)NoNo
User Content — Other (calendar / contacts / messages, on-device)NoNo
Identifiers — Device ID (anonymous install ID for proxy)NoNo
Diagnostics — Crash Data (optional)NoNo
Diagnostics — Performance Data (ML telemetry, optional)NoNo
Location — Coarse Location (proxy ETA, optional)NoNo